U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog
News Source : Securityaffairs.com
News Summary
- Drupal issued a highly critical security patch on May 20 for CVE-2026-9082.
- The vulnerability sits in an API designed to sanitize database queries and prevent SQL injection.
- A flaw in that API means an attacker can send specially crafted requests and inject arbitrary SQL commands on sites using PostgreSQL.
- The result can range from information disclosure to privilege escalation and, in some configurations, remote code execution.
U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog The U.S.
Never miss a story from us, subscribe to our newsletter